Daniel Stenberg warns of risks in curl project

Daniel Stenberg, creator of the widely used curl program, draws parallels between his project and a cyberattack that nearly succeeded two years ago. In an interview in Huddinge, he stresses the importance of trust in open-source software underpinning the internet. An expert warns he could theoretically shut down half the internet.

In March 2024, Andres Freund, a Microsoft employee, discovered a backdoor in the Xz program inserted by Jia Tan under a pseudonym over several years. Xz is used for data compression on millions of servers. The update was halted at the last moment after Freund raised the alarm, foiling the attack.

Daniel Stenberg, who has developed curl since the mid-1990s, sees similarities with his own project. Curl, a tool for digital data transfer, has been installed about 20 billion times in devices like cars, mobile phones, and helicopters. "It was like an insider. One in the team. I also have people in my project I don't meet daily. No face. Just an online name," Stenberg says.

The project began as a way to fetch currency rates and relies on open source, open to contributions from anyone. Stenberg notes the world has changed since 1990s hacker meetups, but the appeal of sharing persists. "We must do something to protect us from that percentage of users trying to find mischief," he says.

KTH professor Pontus Johnson claims Stenberg could "shut down half the internet." Stenberg responds: "Trust is everything I have here. I can't break it or risk it." He acknowledges a security flaw in open source could have severe consequences but stresses suspicions would undermine its use.

Artigos relacionados

Illustration depicting the Linux CopyFail vulnerability enabling root access exploits alongside Ubuntu's DDoS-induced outage.
Imagem gerada por IA

Linux CopyFail exploit threatens root access amid Ubuntu outage

Reportado por IA Imagem gerada por IA

A critical Linux vulnerability known as CopyFail, tracked as CVE-2026-31431, allows attackers to gain root access on systems running kernels since 2017. Publicly released exploit code has heightened risks for data centers and personal devices. Ubuntu's infrastructure has been offline for over a day due to a DDoS attack, hampering security communications.

US undersecretary of state Jacob Helberg said brief curbs on foreign access to Anthropic’s Fable and Mythos models aim to protect critical infrastructure. He spoke in an exclusive interview published on July 16.

Reportado por IA

An open letter opposing NHS England's decision to pull its open-source software from public view amid AI hacking fears has garnered 682 signatures, including from author Cory Doctorow and former health secretary Matt Hancock. Critics argue the policy undermines transparency and security in taxpayer-funded code.

A surge in AI written code submissions is overwhelming volunteers who maintain open source software, leading some to quit the field entirely.

domingo, 12 de julho de 2026, 01:23h

Linus Torvalds calls AI productivity claim unscientific

quinta-feira, 11 de junho de 2026, 11:28h

More libraries may be affected by hacker attack

quarta-feira, 03 de junho de 2026, 17:44h

Tim Berners-Lee introduces personal AI agent Charlie at SXSW London

quarta-feira, 20 de maio de 2026, 21:38h

Google publishes exploit code for unfixed chromium vulnerability

domingo, 10 de maio de 2026, 02:50h

FBI urges router security steps after Russian GRU attacks

Este site usa cookies

Usamos cookies para análise para melhorar nosso site. Leia nossa política de privacidade para mais informações.
Recusar